3D illustration of a laptop with a warning symbol and bug, connected to a swirl, clock, building, locked files, and networked computers, representing cybersecurity threats and data protection.

New Spirals Ransomware Uses IIS Web Shell and PsExec to Encrypt IT Firm in Under 24 Hours

By Published On: July 20, 2026

A new, highly aggressive ransomware strain, dubbed “Spirals,” has emerged, demonstrating an alarming new benchmark in the speed and efficacy of cyberattacks. Recently, an IT services company in South Asia was targeted, falling victim to comprehensive network encryption in under 24 hours from initial breach. This swift and devastating attack, reported by Symantec’s Threat Hunter Team, underscores the escalating threat landscape and the critical need for robust, proactive cybersecurity defenses.

The Rapid Ascent of Spirals Ransomware

The Spirals ransomware, a previously unseen family, executed a highly sophisticated and rapid attack. Threat actors leveraged a combination of established and potentially novel tactics to achieve their objective. The speed of this incident—moving from initial compromise to widespread encryption in less than a day—is particularly concerning. This accelerated timeline highlights a shift towards more efficient and automated attack methodologies, leaving defenders with minimal reaction time.

Technical Deep Dive: IIS Web Shell and PsExec

According to Symantec’s analysis, the attackers utilized an IIS web shell for initial access. An IIS web shell provides remote administrative access to a compromised web server, acting as a persistent backdoor. This allows attackers to execute commands, upload files, and gather information within the network. Once a foothold was established, the perpetrators then deployed PsExec, a legitimate Microsoft sysinternals tool, to move laterally throughout the network. PsExec facilitates the execution of processes on remote systems, making it an ideal tool for spreading malware and gaining control over multiple machines. The combination of these tools allowed for rapid network traversal and payload deployment.

The Rust-Based Payload: A New Adversary

The encryption payload itself is particularly noteworthy. Spirals ransomware is built using Rust, a modern programming language known for its performance, memory safety, and concurrency. While Rust offers significant advantages for application development, it also poses challenges for traditional security solutions due to its low-level control and often unique compiled binaries, which can evade signature-based detections. Symantec suggests that this Rust-based payload appears to be either entirely new or purpose-built specifically for this targeted attack, indicating a high level of customization and sophistication on the part of the attackers.

Remediation Actions and Prevention Strategies

Given the speed and methods employed by the Spirals ransomware, organizations must adopt a multi-layered and proactive defense strategy. Focusing on prevention, detection, and rapid response is paramount.

  • Fortify Web Servers: Regularly patch and configure web servers to minimize vulnerabilities. Implement strong access controls and monitor for suspicious activity, particularly related to IIS processes. Utilize Web Application Firewalls (WAFs) to detect and block web shell uploads and malicious requests.
  • Endpoint Detection and Response (EDR)/Extended Detection and Response (XDR): Deploy advanced EDR/XDR solutions with behavioral analysis capabilities to detect anomalous process execution, such as unusual PsExec activity or the deployment of new, unknown executables.
  • Principle of Least Privilege: Enforce the principle of least privilege for all user accounts and services. This limits the lateral movement capabilities of attackers even if an initial compromise occurs.
  • Network Segmentation: Implement robust network segmentation to contain breaches and prevent ransomware from spreading rapidly across the entire environment.
  • Regular Backups and Disaster Recovery: Maintain isolated, air-gapped, and immutable backups of critical data. Regularly test disaster recovery plans to ensure business continuity in the event of a successful ransomware attack.
  • User Awareness Training: Educate employees about phishing, social engineering, and the importance of reporting suspicious emails or activities. Many initial breaches still rely on human error.
  • Vulnerability Management: Conduct regular vulnerability scans and penetration testing to identify and remediate weaknesses in your infrastructure. Pay close attention to publicly facing services.

Conclusion

The emergence of Spirals ransomware, with its speed, sophisticated toolkit, and Rust-based payload, serves as a stark reminder of the evolving and increasingly dangerous ransomware landscape. The ability for attackers to move from initial breach to full network encryption in under 24 hours demands an immediate re-evaluation of current security postures. Organizations must prioritize proactive defenses, rapid detection and response capabilities, and a continuous commitment to improving their cyber resilience to withstand such aggressive threats.

Share this article

Leave A Comment